Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Home/Threats/AI Chatbots Recommend Malicious Sites, Spreading Malware
Threats

AI Chatbots Recommend Malicious Sites, Spreading Malware

Key Takeaways A new cryptojacking campaign is leveraging AI chatbots to recommend malicious software download sites, steering users toward fake versions of popular utilities. The attack specifically...

Emy Elsamnoudy
Emy Elsamnoudy
May 27, 2026 3 Min Read
78 0

Key Takeaways

  • A new cryptojacking campaign is leveraging AI chatbots to recommend malicious software download sites, steering users toward fake versions of popular utilities.
  • The attack specifically targets users with high-performance GPUs, aiming to maximize cryptocurrency mining profits.
  • Beyond cryptojacking, the threat actors establish persistent remote access via ScreenConnect, enabling potential data theft, lateral movement, or ransomware deployment.
  • Microsoft Defender Experts identified this evolving campaign, which initially relied on search engine poisoning before shifting to AI chatbot manipulation by April 2026.

Cybercriminals are increasingly exploiting the public’s trust in artificial intelligence, engineering a sophisticated cryptojacking operation that manipulates AI chatbot recommendations to distribute malware. This evolving threat lures unsuspecting users to counterfeit software download portals, ultimately compromising their systems for illicit cryptocurrency mining and establishing persistent remote access.

Table Of Content

  • Key Takeaways
  • Hackers Abuse AI Chatbot Recommendations
  • What You Should Do

The campaign focuses on individuals seeking common system utilities and hardware monitoring tools, software frequently used by technology enthusiasts and advanced PC users. When queries are made for popular applications like CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, or K-Lite Codec Pack, users are directed to meticulously crafted fraudulent websites that appear legitimate.

Analysts at Microsoft uncovered this campaign after detecting and subsequently blocking related malicious activities. The threat actors specifically target systems equipped with high-performance GPUs, indicating a strategic focus on maximizing the computational power available for cryptocurrency mining operations.

In a report shared with Cyber Security News (CSN), Microsoft Defender Experts and the Microsoft Defender Security Research Team highlighted that this delivery method “extends social engineering beyond conventional search results and increases the visibility of malicious software recommendations.” The researchers noted that while earlier phases of the campaign employed traditional search engine optimization (SEO) manipulation, a more dangerous tactic involving AI chatbots emerged by April 2026.

The distinctive evolution of this campaign lies in its shift from merely poisoning search engine results to actively influencing responses generated by large language model (LLM)-based AI tools. When users queried AI chatbots for software download advice, the AI systems returned links directing them to domains controlled by the attackers. Microsoft characterized this as “AI search result poisoning,” an advanced application of classic SEO manipulation adapted for widely trusted AI technologies.

The objectives of the campaign extend beyond mere cryptocurrency mining. Attackers also establish persistent remote access on compromised machines using ScreenConnect software. This foothold allows for potential follow-on activities, including data exfiltration, lateral movement within networks, or even the deployment of ransomware. Over 150 malicious domains, predominantly hosted through a dynamic DNS provider frequently associated with threat actor operations, have been identified as part of this extensive infrastructure.

Hackers Abuse AI Chatbot Recommendations

Upon clicking a download link from one of the deceptive sites, victims receive a ZIP archive masquerading as a legitimate software package. This archive contains a malicious DLL file named “autorun.dll,” which is activated when the user launches the seemingly genuine executable. This action initiates the installation of a second malicious file, “vcredist_x64.dll,” which stealthily deploys ScreenConnect, granting attackers full control over the victim’s machine.

Once ScreenConnect establishes a connection with an attacker-controlled server, it delivers “SimpleRunPE.exe.” This binary creates Registry Run keys and scheduled tasks to ensure persistence, configures Microsoft Defender exclusions to evade detection, and employs process hollowing to execute mining code under the guise of a trusted Microsoft-signed binary. The malware supports three prominent mining programs: gminer, lolMiner, and SRBMiner-MULTI. To maintain stealth, it also actively monitors for process monitoring tools such as Task Manager, Process Hacker, and Process Explorer, immediately pausing mining operations if any of these applications are opened.

What You Should Do

  • Verify Download Sources: Always download software directly from official vendor websites. Do not rely solely on links provided by search engines, social media, or AI chatbots, as these can be manipulated.
  • Enable Cloud-Delivered Protection: For organizations, ensure cloud-delivered protection and Endpoint Detection and Response (EDR) in block mode are enabled. This helps intercept threats even before antivirus signatures are updated.
  • Implement Attack Surface Reduction Rules: Configure attack surface reduction rules to defend against common techniques like DLL sideloading and process injection, which are utilized in this campaign. Treat these as baseline security hygiene.
  • Exercise Skepticism: Maintain a healthy skepticism regarding any download link, even those appearing within trusted AI conversations. Cross-reference information and manually navigate to official vendor sites.
  • Monitor for Indicators of Compromise (IoCs): Regularly check network traffic and system logs for the following IoCs:
    • Domains: direct-download.gleeze[.]com, start-download.gleeze[.]com, direct-downloads.giize[.]com, free-download.giize[.]com
    • IP Address: 193.42.11[.]108 (ScreenConnect C2 server)
    • SHA256 Hashes: 16562974deec80e41ef57a71a6de8c03ceb393005fb1432f8d9d82c61294ef8c, 1b2555b09ac62164638f47c8272beb6b0f97186e37d3a54cb84c723ff7a2eee5

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareransomwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Motorola Phones’ Preinstalled App Hijacks Amazon App for Affiliate Fraud

Next Post

CISOs Boost Risk Visibility to Achieve Zero Critical Incidents

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ChainDrop Worm Steals GitHub, Cloud Credentials via 400+ npm Packages
August 7, 2026
UNC6671 Automates Microsoft 365 Data Theft via Session Hijacking
August 7, 2026
Papyrus Ad Fraud Abuses Hidden WebViews to Fake User Engagement
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us